Legal

Privacy Policy

App: Heron Tai Chi (“Heron: Tai Chi for Seniors”)
Bundle ID: batuhan.kacmaz.HeronTaiChi
Last updated: 2026-07-20
Effective date: 2026-07-20

This Privacy Policy describes how Batuhan Kaçmaz (“we”, “us”, “our”) collects, uses, and shares personal information when you use the Heron Tai Chi mobile application (the “App”). It is written for this App specifically and is not a generic template.

We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Turkish Personal Data Protection Law (KVKK, Law No. 6698), and applicable App Store privacy requirements.


1. Quick Summary

Question Short answer
Do I need to create an account? No. The App signs you in anonymously. We never ask for your name, email address, or phone number.
What do you actually store? Your answers to the setup questions (including wellness answers you choose to give), your practice history, any feedback you write, and whether you have a subscription.
Do you collect health information? Yes — but only what you tell us yourself during setup, such as your age, where you feel aches, and how three gentle movement checks felt. We ask for your explicit consent first. See Section 3.2.
Do you sell my personal information? No.
Do you “share” my information for cross-context behavioral advertising (CCPA/CPRA)? No.
Do you track me or use advertising identifiers? No. The App contains no advertising, no analytics SDK, and no crash-reporting SDK.
Do you know my location? No. We never request or store location data.
Where is my data processed? Your practice data is stored in Frankfurt, Germany (EU). Subscription records (RevenueCat) and payments (Apple) are processed in the United States.
How do I delete my data? Email support@wearebasestudio.com — we delete within 30 days. See Section 8.4.
Who is the data controller? Batuhan Kaçmaz, Türkiye — support@wearebasestudio.com

The rest of this document explains each of these points in detail.


2. Who We Are (Data Controller)

The data controller (KVKK: Veri Sorumlusu) for personal information processed by the App is:

We are an independent developer, not a large organisation. We do not have a Data Protection Officer (DPO) under GDPR Article 37, as our processing operations do not require one. For any privacy question, contact us directly at the email above.


3. What Information We Collect

The App has no sign-up screen. You are never asked for your name, email address, phone number, or password. Instead, the App creates an anonymous account for you automatically so that your practice progress can be saved and restored.

3.1 Your Anonymous Account

When you first open the App, we create:

Neither identifier is derived from your Apple ID, your device serial number, your advertising identifier (IDFA), or any other permanent hardware ID. We cannot use them to learn who you are.

For technical reasons, our sign-in provider requires every account to have an email address on file. For anonymous users we generate a synthetic placeholder address internally from the random identifiers described above. It is not a working mailbox, it is never used to contact you, and it contains no personal information about you.

3.2 Setup Answers, Including Health-Related Information

Before your first practice, the App asks a short series of questions so it can build a suitable 28-day plan. You choose what to answer, and you may skip questions. These answers are stored on our servers so your plan survives a reinstall:

This is health-related information. Under GDPR Article 9 and KVKK Madde 6, details about aches and pain, sleep, and physical mobility are treated as a special category of personal data that deserves extra protection. We therefore:

You can withdraw this consent at any time — see Section 8.4.

3.3 Your Practice Activity

As you use the App we record, on our servers:

This is what produces your progress view, your calendar, and your totals.

3.4 Feedback You Write

If you rate a movement or answer the short question at the end of a session, we store your rating, the preset reason you picked (if any), and any free-text note you type. Please do not include your name, contact details, or medical details in free-text notes — they are not needed, and we would rather not hold them.

3.5 Subscription Information

If you purchase a subscription or the lifetime unlock, we store whether you have an active entitlement and which tier it is. Payment itself is handled entirely by Apple. See Section 3.6.

3.6 What Apple and RevenueCat Handle

Source: RevenueCat Apple App Privacy documentation.

3.7 What We Do Not Collect

To be explicit, the App does not collect, request, or store:

3.8 Notifications

If you allow notifications, practice reminders are scheduled locally on your device by iOS. We do not operate a push-notification server and we do not collect a push token. You can turn reminders off at any time in iOS Settings.


4. How We Use Information (Purposes and Legal Bases)

Under GDPR Article 6 (and Article 9 where health-related data is involved), we rely on the following legal bases. The equivalent CCPA/CPRA “business purposes” are listed in the same row.

Purpose Data used GDPR legal basis CCPA/CPRA business purpose
Create and restore your anonymous account so your progress is not lost Device identifier, anonymous user ID Contract (Art. 6(1)(b)) Performing services
Build and adapt your 28-day practice plan to your body and goals Setup answers, including health-related answers Explicit consent (Art. 9(2)(a) with Art. 6(1)(a)) — you may withdraw at any time Performing services
Show your progress, streaks, calendar, and totals Practice session history Contract (Art. 6(1)(b)) Performing services
Unlock paid content and restore purchases Subscription status, anonymous user ID, App Store receipt Contract (Art. 6(1)(b)) Performing services
Prevent payment fraud and abuse of free trials App Store receipt, transaction metadata Legitimate interest (Art. 6(1)(f)) — protecting against fraud Auditing / security
Improve the lessons and fix confusing instructions Movement and session feedback, including free-text notes Consent (Art. 6(1)(a)) — you choose whether to send feedback Internal research
Respond to your support requests The email you send us and its contents Legitimate interest (Art. 6(1)(f)) Customer service

We do not use your data for advertising profiling, automated decision-making producing legal or similarly significant effects (GDPR Article 22), or sale to third parties.


5. Who Receives Your Data (Sub-processors)

We share specific, limited information with the sub-processors below. Each is bound by a Data Processing Agreement to process data only on our instructions, with safeguards equal to or greater than this policy. We do not share your personal information with any other third party, and we do not sell it to anyone.

5.1 Supabase, Inc.

5.2 RevenueCat, Inc.

5.3 Railway Corp.

5.4 Apple Inc.

Apple processes your payment, hosts the App, manages your subscription, and provides the App Store. We never receive your payment details. Apple may also provide us with aggregate, non-identifying App Store statistics such as download and subscription counts. Apple’s practices are governed by Apple’s own privacy policy: https://www.apple.com/legal/privacy/.


6. International Data Transfers

Your practice data — including the health-related setup answers described in Section 3.2 — is stored in Frankfurt, Germany, inside the European Union. It is not transferred to the United States.

Subscription and payment information is different: it is processed in the United States by RevenueCat and Apple, because that is where those services operate.

Our application server is hosted by Railway, a United States company. Your requests pass through it on their way to and from the database, so data may be processed outside the EU in transit, even though it comes to rest in Frankfurt.

For users in the European Economic Area, the United Kingdom, Switzerland, and Türkiye, any transfer outside your region is protected by:

For transfers from Türkiye, we rely on your explicit consent (açık rıza) under KVKK Madde 9 together with the contractual safeguards above, pending an adequacy decision for the recipient countries.


7. How Long We Keep Your Data (Retention)

Data category Retention
Anonymous account and device identifier Until you request deletion, or after 24 months of complete inactivity, whichever comes first
Setup answers, including health-related answers Until you request deletion, withdraw consent, or the 24-month inactivity period above elapses
Practice session history Same as your account — it is the basis of your progress view
Movement and session feedback, including free-text notes 24 months, then deleted
Subscription and purchase records As long as your subscription is active, plus up to 10 years where Turkish tax and commercial law requires us to keep transaction records
Server operational logs 30 days, then automatically deleted
Support email correspondence 24 months from our last reply, then deleted

You can request earlier deletion at any time — see Section 8.4.


8. Your Rights

8.1 Rights under GDPR (EU/UK/EEA users)

You have the following rights:

To exercise these rights, email support@wearebasestudio.com. We respond within 30 days.

8.2 Rights under CCPA/CPRA (California residents)

If you are a California resident, you have the following rights:

We do not sell or share your personal information as those terms are defined in the CCPA/CPRA. We do not engage in cross-context behavioral advertising. You may still send a “Do Not Sell or Share” request to confirm this in writing: support@wearebasestudio.com.

You may use an authorized agent to submit requests on your behalf, subject to verification of authority.

This Privacy Policy is reviewed and updated at least every 12 months, as required by the CCPA.

8.3 KVKK rights (Türkiye)

KVKK Madde 11 kapsamında aşağıdaki haklara sahipsiniz (your rights under Article 11 of the Turkish Personal Data Protection Law):

  1. Kişisel verilerinizin işlenip işlenmediğini öğrenme.
  2. İşlenmişse, buna ilişkin bilgi talep etme.
  3. İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme.
  4. Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme.
  5. Eksik veya yanlış işlenmiş olması hâlinde düzeltilmesini isteme.
  6. KVKK’nın 7. maddesinde öngörülen şartlar çerçevesinde silinmesini veya yok edilmesini isteme.
  7. (5) ve (6) bentleri uyarınca yapılan işlemlerin, aktarıldığı üçüncü kişilere bildirilmesini isteme.
  8. Otomatik sistemler ile analiz edilmesi suretiyle kişiniz aleyhine bir sonucun ortaya çıkmasına itiraz etme.
  9. Hukuka aykırı işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme.

This document also serves as our Aydınlatma Metni (disclosure notice) under KVKK Madde 10. Sections 2 through 7 identify the data controller, the categories of data processed, the purposes of processing, the recipients, the legal grounds, and the transfer safeguards required by that article. Health-related data described in Section 3.2 is özel nitelikli kişisel veri under Madde 6 and is processed only with your explicit consent (açık rıza).

To exercise your rights, write to support@wearebasestudio.com.

8.4 How to Delete Your Data or Withdraw Consent

Because your account is anonymous, we cannot identify you from your name or email — we need the identifier the App holds.

  1. Email support@wearebasestudio.com with the subject “Delete my data”.
  2. We will reply with a short instruction for retrieving your account identifier from the App, so that we delete the right account and no one else’s.
  3. Once confirmed, we delete your account, setup answers, practice history, and feedback within 30 days. Deletion is permanent and cannot be undone.

Deleting the App from your device does not by itself delete data from our servers, because your progress is intentionally preserved so it can be restored if you reinstall. Use the process above if you want it erased.

Please note: deleting your data does not cancel your subscription, because Apple — not us — manages billing. Cancel your subscription in iOS Settings → your name → Subscriptions.


9. Security

We protect your data using:

No method of transmission over the internet or electronic storage is 100% secure. We commit to notify the competent supervisory authority within 72 hours, and affected users without undue delay, of any data breach affecting their personal information, in line with GDPR Articles 33 and 34 and the corresponding KVKK notification duty.


10. Children

Heron Tai Chi is designed for adults, and in particular for practitioners aged 60 and over. It is not directed to children under the age of 13 (or under 16 in the EEA), and it is not listed in the App Store Kids Category. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact support@wearebasestudio.com and we will delete it promptly.

We do not knowingly sell or share the personal information of minors under 16 (CCPA opt-in requirement).


11. Changes to This Policy

We may update this Privacy Policy when we change the way the App works, add or remove a sub-processor, or when laws change. The “Last updated” date at the top reflects the most recent revision. Material changes — in particular any change to what we collect or who receives it — will be communicated in the App before they take effect, and where the change concerns health-related data we will ask for your consent again. The current version is always available at: https://herontaichi.com/privacy.


12. Contact Us

For any privacy question, request to exercise your rights, or breach notification:

We aim to respond within 5 business days, and in any event within 30 days as required by GDPR and CCPA.


Last updated: 2026-07-20. Heron Tai Chi is published by Batuhan Kaçmaz, Türkiye. This policy is written to satisfy Apple App Store Review Guideline 5.1.1(i), GDPR Articles 13–14, CCPA/CPRA, and KVKK Madde 10.